Skip to content

release: website on Astro 7 and security updates - #87

Merged
anurag629 merged 4 commits into
productionfrom
dev
Oct 1, 2026
Merged

anurag629 merged 4 commits into
productionfrom
dev

Conversation

@anurag629

Copy link
Copy Markdown
Member

Ships what's on dev since the 0.4.0 / 0.3.0 release. No package changes and no changesets, so nothing is published to npm. Only the website redeploys.

The deploy now uses @astrojs/cloudflare/entrypoints/server as the Worker main. The build writes website/dist/server/wrangler.json, and wrangler deploy picks it up through website/.wrangler/deploy/config.json.

anurag629 and others added 4 commits October 1, 2026 18:02
The website installed @chatcops/core and @chatcops/server 0.2.0 from npm.
When a release moved them out of that range, changesets rewrote the
ranges and pnpm install --frozen-lockfile failed in the release run.
Use workspace:^ like the widget already does, so the site always runs
the code in this repo and releases don't touch its ranges.
* chore(deps-dev): bump vitest from 3.2.4 to 4.1.11

Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.4 to 4.1.11.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 4.1.11
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(deps): bump website sharp to 0.35.4

Security fix from #81, on top of the vitest 4.1.11 upgrade from #80.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…flare 14 (#85)

Fixes the open Astro security alerts on the docs site, including the
critical image optimization RCE (fixed in 7.2.8).

- wrangler main points at @astrojs/cloudflare/entrypoints/server
- imageService 'compile' keeps build-time image handling (the v14
  default would switch to the Cloudflare Images binding)
- prerenderEnvironment 'node' and wasm32 installs for Starlight's
  Markdown pipeline (satteri), which resolves to its wasm build in the
  Worker bundle
- compressHTML stays true, session: false (no SESSION KV namespace)
- wrangler ^4.146 for the new adapter
…kages (#86)

- happy-dom 16 to 20.14.5 and vite to 6.4.3 in the widget (dev only)
- refresh body-parser, form-data, js-yaml, nanoid, path-to-regexp,
  picomatch, postcss, postcss-selector-parser, qs and yaml to their
  patched versions within the same major (lockfile only)
@anurag629
anurag629 merged commit 12c01d3 into production Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant